Threat reportMalwareTL-2026-1344
AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)
AtlasRAT: Four-Stage In-Memory Loader Chain Delivers (TL-2026-1344), also tracked as Atlas RAT, is a high-severity malware campaign, first published 2026-07-15 and last reviewed 2026-07-30. It is attributed to Void Arachne (China) with medium confidence, affects Generic Windows endpoints (consumer/enterprise), maps to 51 MITRE ATT&CK techniques (T1005, T1008, T1021.001), and is covered by 9 detection rules and 61 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 51MITRE ATT&CK
- Actors
- 1Void Arachne
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 61Indicators of compromise
Key facts for TL-2026-1344
- Threat ID
- TL-2026-1344
- Also known as
- Atlas RAT, AtlasCross
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Void Arachne
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- consumer, technology, finance, government administration
- Target regions
- china, japan, malaysia, philippines, thailand, indonesia, singapore, india
- Detection rules
- 9
- Indicators of compromise
- 61
- Updates
- 2026-07-30 · 2 updates · revalidated 2× · latest source
Malware and tooling in AtlasRAT: Four-Stage In-Memory Loader Chain Delivers
Malware and tooling: AtlasRAT, MainDll.dll
How AtlasRAT: Four-Stage In-Memory Loader Chain Delivers works
AhnLab ASEC documented AtlasRAT, a modular remote access trojan delivered through a four-stage, largely in-memory loader chain that begins with a Delphi executable disguised as "AGE Flash Player." The final payload uses ChaCha20-over-TLS C2 communication with a spoofed Microsoft certificate, injects into WeChat, performs offline keylogging, and enumerates 33 security products; ASEC tracked 43 active AtlasRAT C2 servers as of 2026-06-09 and found partial marker overlap ("By@V<") with the Silver Fox threat actor's related "Atlas RAT"/AtlasCross campaigns, though the two variants use different handshake strings (BFuck vs. SFuck).
AtlasRAT is a commercial-grade remote access trojan tracked by AhnLab ASEC in a report titled "Not Every Fox is Silver: Inside an AtlasRAT Loader Chain" (2026-07-15). The infection begins with a Delphi-compiled executable masquerading as an "AGE Flash Player" installer (Stage 1). This dropper decrypts and loads an embedded PE image (Stage 2) entirely in memory, which in turn reconstructs downloader shellcode from eight separately encrypted fragments (Stage 3). The shellcode reflectively maps and executes MainDll.dll, a 32-bit RAT payload, via a technique ASEC labels ServiceRun (Stage 4). No stage other than the initial dropper is written to disk, minimizing forensic artifacts and defeating static AV scanning of intermediate stages.
Once resident, AtlasRAT establishes command-and-control over TLS to 150.158.50.175:443, opening every session with an 8-byte handshake marker "BFuck\0\0\0" (hex 42 46 75 63 6b 00 00 00). The TLS session itself is wrapped in an additional application-layer ChaCha20 stream cipher, and the certificate presented is self-signed but spoofs the subject "CN=update.microsoft.com, O=Microsoft Corporation, C=US" (SHA-256 fingerprint 3f152103ea35c0f7feb205651a91e3c946b8057d1ea6f046ffc44fa611fd0267) to blend into HTTPS traffic logs and evade naive certificate-pinning defenses. ASEC's telemetry identified 43 active AtlasRAT C2 servers as of 2026-06-09, indicating an operationally mature, multi-tenant or affiliate-style infrastructure footprint consistent with a commercially distributed RAT rather than a single-operator tool.
The final-stage payload is built around a modular plugin architecture. Observed capabilities include offline/buffered keylogging (keystrokes cached locally and exfiltrated in batches rather than streamed live, reducing detectable network chatter), DLL injection into WeChat.exe to intercept or manipulate the popular Chinese messaging client, and a security-product inventory routine that fingerprints the presence of 33 distinct security executables on the host — behavior consistent with pre-attack reconnaissance intended to select an evasion profile or abort execution on well-defended hosts. General process/file enumeration and system information collection round out the plugin set. Persistence markers and configuration state are dropped to C:\Users\Public\Documents\ using the filenames offline.ini, MODIf.html, AtlasPro.ini, and Wxfun.dll, giving defenders concrete host-based indicators even though the loader chain itself is fileless.
ASEC's analysis explicitly compares AtlasRAT to previously reported "Silver Fox" activity. Silver Fox (also tracked as Void Arachne, SwimSnake, UTG-Q-1000, and "The Great Thief of Valley") is a Chinese-origin threat actor with a multi-year lineage running from Gh0st RAT derivatives through ValleyRAT, Gh0stCringe, HoldingHands RAT, and Winos 4.0 to the current "Atlas RAT" / AtlasCross family. Independent reporting (Hexastrike, The Hacker News, March 2026) documents a related Silver Fox campaign delivering an "Atlas RAT" via a triple-nested Setup Factory installer trojanizing a stolen Autodesk binary, dynamically resolving APIs via PEB walking, decrypting an embedded Gh0st RAT configuration, and downloading second-stage shellcode over raw TCP (port 9899) to a C2 domain bifa668[.]com (registered 2025-10-27, resolving to 61.111.250.139, ASN 138195 MOACK.Co.LTD, South Korea) fronted by nameservers a.share-dns.com/b.share-dns.net. That campaign's handshake, "SFuck\0\0\0" (hex 53 46 75 63 6b 00 00 00), differs from AtlasRAT's "BFuck" marker but the two samples share the distinct "By@V<" internal marker string, and both ultimately reflectively load a RAT DLL named/labeled as part of an "Atlas" family — the basis for ASEC's assessment of partial overlap without full identity. The related Silver Fox campaign used eleven brand-impersonating delivery domains (Zoom, Signal, Telegram, Surfshark VPN, Microsoft Teams, QuickQ VPN, UltraViewer, Trezor, KeFuBao, WangWang, plus one unattributed) registered in a single wave on 2025-10-27, code-signed installers abusing a stolen Extended Validation certificate issued to a Vietnamese entity (DUC FABULOUS CO., LTD, Hanoi), and native CLR-hosted PowerShell execution that disables AMSI, ETW, Constrained Language Mode, and ScriptBlock logging without ever spawning powershell.exe. Both the AtlasRAT and the related Silver Fox Atlas RAT lineage specifically target Chinese-speaking users and enumerate/disable Chinese security products (360 Total Security/360 Safe, Huorong, Kingsoft, QQ PC Manager), and both inject into or monitor WeChat.
This skeleton is scoped strictly to the ASEC-documented AtlasRAT sample and its 43-server C2 tracking; the related Silver Fox/AtlasCross infrastructure (bifa668[.]com, the eleven typosquat domains, and the stolen Autodesk/Setup Factory delivery chain) is documented here as corroborating attribution/overlap context, sourced independently from Hexastrike and The Hacker News reporting on the broader Silver Fox campaign active November 2025–March 2026.
MITRE ATT&CK techniques used in TL-2026-1344
Collection
T1005 Data from Local System; T1056 Input Capture; T1074.001 Data Staged: Local Data Staging
Command and Control
T1008 Fallback Channels; T1071.001 Application Layer Protocol: Web Protocols; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding; T1571 Non-Standard Port; T1573.001 Encrypted Channel: Symmetric Cryptography
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1563.002 Remote Service Session Hijacking: RDP Hijacking
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.001 Masquerading: Invalid Code Signature; T1036.005 Match Legitimate Resource Name or Location; T1055.001 Process Injection: Dynamic-link Library Injection; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading
Persistence
T1037.001 Logon Script (Windows); T1053.005 Scheduled Task/Job: Scheduled Task; T1197 BITS Jobs; T1543.003 Create or Modify System Process: Windows Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056.001 Input Capture: Keylogging
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518.001 Security Software Discovery
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1106 Native API; T1129 Shared Modules; T1204.002 User Execution: Malicious File
defense-impairment
T1112 Modify Registry; T1553.002 Code Signing; T1553.006 Code Signing Policy Modification; T1685 Disable or Modify Tools; T1685.001 Disable or Modify Windows Event Log
Initial Access
T1195 Supply Chain Compromise; T1195.002 Compromise Software Supply Chain; T1566 Phishing; T1566.002 Phishing: Spearphishing Link
Impact
Privilege Escalation
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.001 Develop Capabilities: Malware; T1588.003 Obtain Capabilities: Code Signing Certificates
Affected products and versions in AtlasRAT: Four-Stage In-Memory Loader Chain Delivers
- Generic — Windows endpoints (consumer/enterprise)
Vulnerable versions: Windows 10; Windows 11; Windows Server (general)
Remediation for AtlasRAT: Four-Stage In-Memory Loader Chain Delivers
Immediate actions
- Block C2 IPs 150.158.50.175, 108.187.7.84, 116.204.169.70, 143.92.32.49, 143.92.32.65, 143.92.32.72, and 61.111.250.139 at perimeter firewall/proxy
- Sinkhole or block DNS resolution for bifa668.com and the eleven Silver Fox typosquat delivery domains
- Hunt for host artifacts offline.ini, MODIf.html, AtlasPro.ini, and Wxfun.dll under C:\Users\Public\Documents\
- Revoke trust for/flag the stolen Extended Validation code-signing certificate issued to DUC FABULOUS CO., LTD
- Alert on TLS sessions opening with the 8-byte handshake markers 42 46 75 63 6b 00 00 00 ("BFuck") or 53 46 75 63 6b 00 00 00 ("SFuck")
Workarounds
- Block execution of Setup Factory (SFX 7.0/8.0) extracted binaries from %TEMP%_ir_sf[7|8]_temp_0 paths via application control policy
Longer-term hardening
- Deploy EDR with in-memory/reflective-loading detection (ETW-based, not signature-based, since payload is fileless after Stage 1)
- Enforce application allowlisting to block unsigned/renamed installer executables masquerading as Flash Player or Autodesk products
- Monitor and alert on DLL injection targeting WeChat.exe and other messaging clients
- Deploy TLS certificate-transparency / JA3-style fingerprinting to catch spoofed 'update.microsoft.com' self-signed certs
- User awareness training on fake VPN/messaging-app installers as a Silver Fox delivery vector
Timeline of AtlasRAT: Four-Stage In-Memory Loader Chain Delivers
- The Extended Validation code-signing certificate for "DUC FABULOUS CO., LTD" (Hanoi, Vietnam) later abused across Silver Fox's related Atlas RAT installers is issued; per Hexastrike the certificate remains valid through 2027-05-15.
- Silver Fox registers eleven brand-impersonating typosquat delivery domains (Zoom, Signal, Telegram, Surfshark, Microsoft Teams, and others) plus the bifa668[.]com C2 domain in a single registration wave, per Hexastrike analysis of the related Atlas RAT campaign.
- First identified related Atlas RAT standalone executables appear, the start of a four-month wave of roughly twenty Silver Fox Atlas-family DLL samples observed by Hexastrike.
- Silver Fox's AtlasCross RAT campaign targeting Chinese-speaking users is observed extending across Japan, Malaysia, the Philippines, Thailand, Indonesia, Singapore, and India.
- Tax-themed phishing lures targeting Indian users are reported (eSentire, cited via The Hacker News) as part of the broader Silver Fox Atlas campaign.
- Approximate start of ASEC's 180-day VirusTotal retrohunt window (per ASEC's English-language follow-up report) that surfaced the 146 AtlasRAT samples.
- The Hacker News publishes reporting on Silver Fox's AtlasCross RAT campaign and fake domains.
- Infection timestamp recorded inside a dropped Silver Fox Atlas RAT configuration file, per Hexastrike's sample analysis.
- Hexastrike observes the newest related Silver Fox Atlas RAT payload sample, one day before publishing its analysis.
- Dark Lab publishes analysis of Silver Fox's dual-pronged ValleyRAT distribution strategy, documenting continued activity by the actor cluster circumstantially linked to AtlasRAT.
- Hexastrike publishes detailed technical analysis "Trust the Tunnel, Get the Trojan," documenting the Setup Factory/stolen-Autodesk loader chain, SFuck handshake, and bifa668[.]com C2 infrastructure.
- cybersecuritynews.com publishes coverage of Silver Fox's stolen EV code-signing certificate abuse (DUC FABULOUS CO.,LTD, thumbprint 2C1D12F8BBE0827400A8440AF74FFFA8DCC8097C) in the AtlasCross RAT campaign.
- Persistence86.dll PDB path references build/version labels 'atlasPro验证版2026.6.2' / 'atlasPro Trial Version 2026.6.2', confirming the persistence/UAC-bypass module ships from the same versioned builder pipeline as MainDll.dll.
- AhnLab ASEC's telemetry records 43 active AtlasRAT command-and-control servers, the infrastructure-scale data point cited in the eventual ASEC report.
- AhnLab ASEC publishes "Not Every Fox is Silver: Inside an AtlasRAT Loader Chain," documenting the four-stage in-memory loader, BFuck handshake, spoofed Microsoft certificate, WeChat DLL injection, offline keylogging, 33-product security enumeration, and partial marker overlap with Silver Fox's Atlas RAT variant.
- ASEC's 180-day retrospective VirusTotal hunt surfaces 146 unique AtlasRAT-family samples (x86/x64 builder variants), confirming sustained active distribution rather than an isolated incident.
- AhnLab ASEC publishes a follow-up AtlasRAT analysis, identifying the same bifa668.com C2 domain and Wxfun.dll WeChat-injection tradecraft as the 2026-07-15 report, delivered via a trojanized 'AGE Flash Player' installer (FlashPlay.exe).
Update history for TL-2026-1344
- 2026-07-30 — AtlasRAT: New Modular RAT Distributed via Fake Flash Player Installer Uses Four-Stage In-Memory Loader: What changed No field escalations. Severity (HIGH), exploitability (ACTIVE), status (ACTIVE), and attribution_confidence (MEDIUM) are unchanged. ASEC's English-language follow-up newly documents a Persistence86.dll module handling BITS-job
- 2026-07-28 — AtlasRAT: Modular Multi-Stage In-Memory RAT Targeting WeChat via Trojanized 'AGE Flash Player' Installer (Silver Fox C2 Overlap): What changed No severity/exploitability/status escalation (HIGH/ACTIVE/ACTIVE/MEDIUM-confidence attribution all unchanged). The new ASEC report expands infrastructure scale (180-day VT retrohunt: 146 samples, 8 additional C2 IPs) and adds p
Sources cited for AtlasRAT: Four-Stage In-Memory Loader Chain Delivers
- Not Every Fox is Silver: Inside an AtlasRAT Loader Chain
- Trust the Tunnel, Get the Trojan: Silver Fox Delivers Atlas RAT via Weaponized VPN Installers
- Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains
- Analyzing the Silver Fox tax campaign and the new ABCDoor backdoor
- TA4922: The Suspected Chinese Crime Group is Going Global
- New Silver Fox Attack Pushes Malware Through Software Update Lures
- Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia
- Silver Fox group uses new Rust-based MODBEACON RAT
- SilverFox ValleyRAT Campaign Uses Eight-Stage Chain to Deploy Kernel Rootkit
Detection coverage for TL-2026-1344
As of 2026-07-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1344 across Splunk SPL, Microsoft KQL and Sigma, covering 61 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.